IBuild · from ₹1,50,000
A web application, built and attacked by the same person.
4–8 weeks · review included · fixed price
For founders building something with users, logins and data — a portal, a marketplace, an internal tool, a SaaS product — who would rather pay one person to do the whole thing properly.
Who this is for
Users, logins and data. Not a brochure.
You have users who log in and data they trust you with, and you'd rather pay one person who can design, build and test the thing than coordinate a designer, a developer and — usually never — a security tester.
It's not for a marketing site with no accounts behind it. I build content sites only as part of a larger product; on their own you'll get better value elsewhere, and I'll say so on the call.
What a build includes
Every build, at every price, goes through all of this.
Discovery, design, development — with security in every one of those, not bolted on at the end.
- 01Discovery and planningRequirement sessions, user flows, architecture and design direction before anything is coded.
- 02DesignCustom, responsive UI — desktop and mobile — in a visual system that fits your brand. No templates.
- 03DevelopmentNext.js, TypeScript and Tailwind; Supabase (managed Postgres); deployed on Vercel. Authentication, profiles and dashboards, database, inquiry management, an admin panel.
- 04Security review, before launchIn the final week I run the same pre-launch review I sell standalone for ₹50,000 against what I built. Findings in writing, fixed before launch.
- 05After launch5 working days to review and accept, then 30 days of bug fixes on anything in scope. New features are quoted separately, in writing.
Security, during the build
The part nobody else at this price does.
This is what changes when the person building it knows he'll be the one attacking it in week six.
- 01Access control designed on paper before the first screenWho can see and do what — and what happens when they try what they shouldn't.
- 02Everything that matters enforced on the serverPermissions, prices, scores, status changes. Nothing important is decided in the browser.
- 03No secrets in the repository, everScanned across the full git history; Gitleaks in CI keeps it that way.
- 04Security headers and a strict CSP from the first deployThis site is the example — check its headers.
- 05Dependencies audited before launchKnown vulnerabilities cleared before anything goes live.
- 06Input handling reviewed against the OWASP Top 10Injection, XSS, broken access control, CORS, session handling.
Timeline and price
Fixed price, agreed in writing before work starts. Four to eight weeks, depending on scope and how quickly you can give feedback.
- ₹1,50,000
- from · build with pre-launch review
- ₹2,50,000
- from · build with a full penetration test
- 4–8 weeks
- typical build timeline
- 30 days
- of in-scope bug fixes after acceptance
IIBuilds with a full penetration test
Payments, health data, personal information at scale, an enterprise customer or an investor's security questionnaire: builds from ₹2,50,000 include a full penetration test of the application and its API in the final two weeks — findings ranked by severity with reproduction steps, a report in the public sample format, and one retest of the fixes within 30 days.
When the review isn't enough.
IIIWhy the floor is where it is
A build is four to eight weeks of one person's full attention, and one of those weeks is spent trying to break what I made. Below that number, that week is the one that goes — and then I'm selling what everyone else sells.
What you get: source in a repository you own, the application running on your own accounts, the written findings from the review, and a handover — written docs plus a call — on how it's built and how to run it.
Below ₹1.5 lakh, the testing is what gets cut.
Questions founders ask
Before you start a build
What does a build cost?
From ₹1,50,000 with the pre-launch security review included, and from ₹2,50,000 with a full penetration test. Fixed price, agreed in writing before work starts. Payment is 40% to start, 30% mid-way, 30% at launch.
How long does a build take?
4–8 weeks, depending on scope and how quickly you can give feedback. One of those weeks is spent attacking what I built.
Who owns the code and the accounts?
You do. The application is deployed on your Vercel, your Supabase and your domain, and the source lives in a repository you own.
What happens after launch?
5 working days to review and accept, then 30 days of bug fixes on anything within the agreed scope. New features are quoted separately, in writing.
Will you build a marketing site?
Only as part of a larger product or at the same floor price. On its own you'll get better value elsewhere, and I'll say so on the first call.
IVStart a build
Tell me what you're building.
Two lines is enough. I reply within one working day; the first call is free and about fit.